First published: Tue Mar 11 2025(Updated: )
SAP NetWeaver Application Server ABAP allows malicious scripts to be executed in the application, potentially leading to a Cross-Site Scripting (XSS) vulnerability. This has no impact on the availability of the application, but it can have some minor impact on its confidentiality and integrity.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver Application Server |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-25242 is classified as a moderate severity vulnerability due to its potential for Cross-Site Scripting (XSS) attacks.
To fix CVE-2025-25242, ensure you apply the latest security patches released by SAP for the NetWeaver Application Server ABAP.
CVE-2025-25242 can lead to unauthorized script execution, potentially impacting the confidentiality of user information.
Yes, CVE-2025-25242 can be exploited remotely by attacking users of the SAP NetWeaver Application Server ABAP.
CVE-2025-25242 can lead to Cross-Site Scripting (XSS) attacks, allowing attackers to execute malicious scripts in the context of a user session.